Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Attackers are actively exploiting WordPress CVE-2026-87902, a critical CVSS 9.2 flaw that enables unauthenticated local PHP file inclusion and conditional remote code execution.

Threat actors have begun actively exploiting CVE-2026-87902, a critical vulnerability in WordPress Core, only hours after details and security updates became publicly available.
The vulnerability carries a CVSS score of 9.2 and allows an unauthenticated attacker to include arbitrary local PHP files outside the active theme directories. Under specific server and theme conditions, the flaw can be escalated to remote code execution (RCE).
CVE-2026-87902 at a Glance
| Detail | Information |
|---|---|
| CVE | CVE-2026-87902 |
| Product | WordPress Core |
| Severity | Critical – CVSS 9.2 |
| Authentication | Not required |
| Primary Issue | Path traversal / Local PHP file inclusion |
| Potential Impact | Remote Code Execution |
| Affected | WordPress 4.7.0 through 7.1.1 |
| Exploitation | Active |
WordPress fixed the vulnerability in 7.1.2, with security fixes also backported to supported older branches.
How the Attack Works
The vulnerability exists in WordPress's get_page_template() page-template resolution process. A specially crafted request can cause WordPress to load a readable PHP file located outside the expected theme directory.
Successful RCE requires additional conditions, including:
- The active parent or child theme has a top-level directory beginning with
page-, such aspage-templates. - A suitable local PHP file is present and readable by the web-server account.
Attackers have already been observed targeting:
/usr/local/lib/php/pearcmd.php
By abusing pearcmd.php, attackers can write malicious PHP files to disk and potentially execute attacker-controlled code.
The attack path can be summarized as:
Malicious Request → Path Traversal → Local PHP Inclusion → pearcmd.php Abuse → PHP File Write → Potential RCE
Exploitation Began Within Hours
Patchstack initially detected probing on September 22, 2026, less than five hours after WordPress 7.1.2 was released. Early activity focused on including harmless WordPress files to determine whether websites were vulnerable.
Attackers subsequently moved to active exploitation using pearcmd.php to write PHP files. Reported filenames include:
wp-pear-rce-flag.phppoc87902.phpluci_<random>.phpzeta_<random>.php
Previdian also recorded exploitation attempts against its honeypots beginning September 23.
On September 25, CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that the vulnerability is being exploited in the wild.
What WordPress Administrators Should Do
Administrators should immediately upgrade to a patched WordPress release, including:
- 7.1.2 or later
- 7.0.6 or later
- 6.9.9 or later
- 6.8.10 or later
- Appropriate security backport for older supported branches
Because exploitation began shortly after disclosure, administrators should not rely only on patching. Previously exposed systems should also be checked for unexpected PHP files, modifications under /tmp and /var/tmp, suspicious page-template requests, unknown administrator accounts, web shells and unusual outbound connections.
Security Takeaway
CVE-2026-87902 demonstrates how quickly attackers can weaponize newly disclosed vulnerabilities.
Disclosure → Vulnerability Probing → Local File Inclusion → PHP File Write → Potential Server Compromise
Although remote code execution requires specific environmental conditions, active exploitation has already been confirmed. WordPress administrators should therefore prioritize patching and investigate systems that were exposed before the security update was installed.
Related reporting
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Warlock ransomware attackers exploit Microsoft SharePoint vulnerabilities to gain initial access, disable security tools and distribute ransomware across critical infrastructure networks.
Apple CoreGraphics Zero-Day PoC Emerges as WhatsApp PDF Checks Raise Delivery Questions
A public PoC for Apple CoreGraphics CVE-2026-86950 demonstrates memory corruption through a malicious PDF, while new WhatsApp PDF protections raise questions about a possible delivery path.
Kiteworks Fixes Critical Vulnerability Discovered During Emergency Shutdown
Kiteworks patched a previously unknown critical vulnerability discovered during a nine-hour precautionary shutdown prompted by intelligence about a potential cyberattack, with no evidence of exploitation.


